M2 · VPC-native networking
NEGs
16 / 61

Container-native load balancing removes the node hop

GKE-managed Layer 7 load balancers use GCE_VM_IP_PORT Network Endpoint Groups (NEGs) so health checks and requests target Pod IP and port directly.

1ClientConnects to an external or internal Application Load Balancer.
2FrontendTerminates the connection and evaluates routing policy.
3Backend serviceSelects a healthy zonal NEG.
4NEG endpointMaps directly to the Pod alias IP and target port.
5Ready PodReceives traffic without a NodePort and kube-proxy hop.
A readiness gate can keep a Pod out of service until the load balancer sees it as healthy.